All Practice Exams

100+ Free ISO/IEC 27002 Foundation Practice Questions

Prepare for the PECB Certificate Holder in ISO/IEC 27002 Foundation exam with instant access — no signup required.

✓ No registration✓ No credit card✓ No hidden fees✓ Start practicing immediately
Not published Pass Rate
100+ Questions
100% Free

Loading practice questions...

2026 Statistics

Key Facts: ISO/IEC 27002 Foundation Exam

40 MCQ, 1h

Exam Format

PECB List of Exams

Closed-book

Exam Type

PECB

70%

Passing Score

PECB standard passing criteria

93 controls

ISO/IEC 27002:2022 Controls

ISO/IEC 27002:2022

4 themes

Control Structure (Organizational, People, Physical, Technological)

ISO/IEC 27002:2022

USD 500

Exam-only Fee (Foundation level)

PECB

PECB ISO/IEC 27002 Foundation is a closed-book, 40-question, 1-hour multiple-choice exam with a 70% passing score. It targets managers, consultants, and professionals who need to understand and interpret the information security controls of ISO/IEC 27002:2022 in the context of an ISMS. No prerequisites; the certificate requires only passing the exam and signing the PECB Code of Ethics.

Sample ISO/IEC 27002 Foundation Practice Questions

Try these sample questions to test your ISO/IEC 27002 Foundation exam readiness. Each question includes a detailed explanation. Start the interactive quiz above for the full 100+ question experience with AI tutoring.

1What is the primary purpose of ISO/IEC 27002?
A.To provide guidance on selecting, implementing, and managing information security controls
B.To define mandatory certification requirements for an information security management system
C.To specify the audit methodology for certifying an ISMS
D.To replace ISO/IEC 27001 as the certifiable requirements standard
Explanation: ISO/IEC 27002 is a guidance standard that helps organizations determine and implement commonly accepted information security controls. It explains how to apply controls; it does not contain requirements against which an organization is certified.
2How are the information security controls in ISO/IEC 27002:2022 organized?
A.Into 14 clauses aligned with the 2013 edition
B.Into four themes: organizational, people, physical, and technological
C.Into the five functions of the NIST Cybersecurity Framework only
D.Into the clauses of the Plan-Do-Check-Act cycle
Explanation: The 2022 edition restructured its controls into four themes: organizational (37), people (8), physical (14), and technological (34) controls, totalling 93 controls. This replaced the 14-clause structure of the 2013 edition.
3Which of the following is one of the four control themes introduced in ISO/IEC 27002:2022?
A.Managerial
B.Procedural
C.People
D.Environmental
Explanation: The four themes are organizational, people, physical, and technological. The 'people' theme contains controls concerning individual personnel, such as screening, awareness training, and remote working.
4The three fundamental properties of information security, often called the CIA triad, are:
A.Control, identification, authentication
B.Confidentiality, identity, accountability
C.Compliance, integrity, auditability
D.Confidentiality, integrity, availability
Explanation: Information security is defined as the preservation of confidentiality, integrity, and availability of information. Confidentiality means information is not made available to unauthorized entities, integrity means accuracy and completeness are protected, and availability means information is accessible when needed.
5Confidentiality, as a property of information security, is best described as:
A.Ensuring information is not made available or disclosed to unauthorized individuals, entities, or processes
B.Ensuring information is accurate and complete
C.Ensuring information is accessible and usable on demand
D.Ensuring information can be traced to its origin
Explanation: Confidentiality is the property that information is not made available or disclosed to unauthorized individuals, entities, or processes. Controls such as encryption, access control, and classification support confidentiality.
6Which scenario primarily represents a failure of integrity rather than confidentiality or availability?
A.An ex-employee downloads the customer database before leaving
B.A payment record is altered in transit so funds are sent to a different account
C.A ransomware attack encrypts production file servers
D.A distributed denial-of-service attack takes a web shop offline
Explanation: Integrity is the property of safeguarding the accuracy and completeness of information and processing methods. Unauthorized alteration of a payment record in transit is a direct breach of integrity.
7Availability, in the context of information security, means:
A.Information is protected against unauthorized disclosure
B.Information is backed up to an off-site location
C.Information is accessible and usable upon demand by an authorized entity
D.Information is kept up to date and complete
Explanation: Availability is the property of being accessible and usable upon demand by an authorized entity. Redundancy, backups, capacity management, and resilience measures all support availability.
8How does ISO/IEC 27002 distinguish cybersecurity from information security?
A.Cybersecurity covers only personal data, while information security covers all data
B.Cybersecurity and information security are synonyms with identical scope
C.Information security applies only to paper records, cybersecurity only to digital records
D.Cybersecurity is a subset of information security focused on protecting cyberspace to preserve the security of information and associated assets
Explanation: Information security protects information in all its forms and locations. Cybersecurity is focused on the protection of cyberspace — the networked digital environment — to preserve the security of information and assets within it, so it is commonly treated as a subset of information security.
9What is the relationship between ISO/IEC 27001 Annex A and ISO/IEC 27002?
A.Annex A lists the reference controls, while ISO/IEC 27002 provides implementation guidance for those same controls
B.Annex A contains unique controls unrelated to ISO/IEC 27002
C.ISO/IEC 27002 contains requirements and Annex A contains guidance
D.Annex A is optional reading with no connection to ISO/IEC 27002
Explanation: ISO/IEC 27001 Annex A lists the reference information security controls that organizations consider during risk treatment. ISO/IEC 27002 provides the detailed guidance on the purpose and implementation of those same controls, and Annex A includes a mapping to ISO/IEC 27002.
10Can an organization be certified as conforming to ISO/IEC 27002?
A.Yes, organizations can certify their ISMS against ISO/IEC 27002
B.No, ISO/IEC 27002 is a guidance document; certification is performed against ISO/IEC 27001 requirements
C.Yes, but only through accredited national bodies
D.No, because ISO/IEC 27002 is only for government agencies
Explanation: ISO/IEC 27002 contains guidance rather than requirements ('should' statements rather than 'shall' requirements), so organizations cannot be certified against it. ISMS certification is performed against the requirements of ISO/IEC 27001.

About the ISO/IEC 27002 Foundation Exam

The PECB ISO/IEC 27002 Foundation certification demonstrates a general knowledge of the information security controls of ISO/IEC 27002:2022 and the fundamental concepts of information security, cybersecurity, and privacy. The exam covers two competency domains: fundamental principles and concepts, and the 93 controls organized into four themes — organizational, people, physical, and technological — including how ISO/IEC 27002 relates to ISO/IEC 27001 and ISO/IEC 27003.

Questions

40 scored questions

Time Limit

1 hour

Passing Score

70%

Exam Fee

USD 500 exam-only (Foundation level); exam fee included when taken with a PECB training course (PECB (Professional Evaluation and Certification Board))

ISO/IEC 27002 Foundation Exam Content Outline

~30% (weighting not officially published)

Domain 1: Fundamental Principles and Concepts of Information Security, Cybersecurity, and Privacy

Confidentiality, integrity, and availability; the scope of information security vs cybersecurity and privacy protection; ISMS fundamentals and the PDCA cycle; information security risk assessment and treatment; the ISO/IEC 27000 family (ISO/IEC 27001 requirements, ISO/IEC 27003 implementation guidance, ISO/IEC 27004 measurement, ISO/IEC 27005 risk management); the 2022 revision's structure, control attributes, and new controls

~70% (weighting not officially published)

Domain 2: Information Security Controls Based on ISO/IEC 27002

The 93 controls of ISO/IEC 27002:2022 across four themes: 37 organizational controls (policies, roles, threat intelligence, supplier and cloud security, incident management 5.24-5.28, business continuity, legal compliance); 8 people controls (screening, employment terms, awareness training, disciplinary process, remote working, event reporting); 14 physical controls (perimeters, entry, monitoring, environmental threats, clear desk, media, utilities, cabling, disposal); 34 technological controls (endpoints, privileged access, authentication, malware, vulnerability and configuration management, backup, logging, monitoring, network security, cryptography, secure development, change management)

How to Pass the ISO/IEC 27002 Foundation Exam

What You Need to Know

  • Passing score: 70%
  • Exam length: 40 questions
  • Time limit: 1 hour
  • Exam fee: USD 500 exam-only (Foundation level); exam fee included when taken with a PECB training course

Keys to Passing

  • Complete 500+ practice questions
  • Score 80%+ consistently before scheduling
  • Focus on highest-weighted sections
  • Use our AI tutor for tough concepts

ISO/IEC 27002 Foundation Study Tips from Top Performers

1Memorise the four control themes and their counts: organizational 37, people 8, physical 14, technological 34 — 93 controls total
2Learn the control numbering scheme: 5.x organizational, 6.x people, 7.x physical, 8.x technological, so you can locate any control by its number
3Master the incident management family 5.24-5.28 in sequence: planning, assessment, response, learning, evidence collection
4Understand control attributes: control type (preventive, detective, corrective) and cybersecurity concepts (Identify, Protect, Detect, Respond, Recover)
5Know the differences between related controls: 5.19 vs 5.20 vs 5.22 (supplier lifecycle), 8.15 vs 8.16 (logging vs monitoring), 8.11 vs 8.12 (masking vs DLP)
6Drill the fundamentals: CIA triad definitions, risk assessment steps (identification, analysis, evaluation), and the four risk treatment options

Frequently Asked Questions

What is the PECB ISO/IEC 27002 Foundation exam format?

The exam consists of 40 multiple-choice questions with a 1-hour time limit. It is closed-book: no reference materials, standards copies, or notes are permitted. The passing score is 70%. The exam can be taken online (proctored via the PECB Exams app) or in paper form at authorised PECB exam venues, and is available in English.

What is the difference between ISO/IEC 27001 and ISO/IEC 27002?

ISO/IEC 27001 is the requirements standard against which an ISMS is certified; its Annex A lists reference controls. ISO/IEC 27002 is a guidance standard that explains the purpose and implementation of those same controls and cannot itself be certified against. The PECB ISO/IEC 27002 Foundation exam tests your understanding of the ISO/IEC 27002 controls and how the two standards relate.

How many controls does ISO/IEC 27002:2022 contain and how are they organized?

The 2022 edition contains 93 controls organized into four themes: 37 organizational controls, 8 people controls, 14 physical controls, and 34 technological controls. This replaced the 2013 edition's 114 controls in 14 clauses. Each control is tagged with attributes (control type, information security properties, cybersecurity concepts aligned to the NIST CSF) and presented with a purpose statement and implementation guidance.

Are there prerequisites for the ISO/IEC 27002 Foundation certification?

No. There are no prerequisites for the training course or exam, and the certificate requires no professional experience, audit experience, or project experience. To be certified you only need to pass the exam and sign the PECB Code of Ethics.

What happens if I fail the exam?

According to the official PECB course page, if you fail you can retake the exam within 12 months for free. PECB policy requires a 15-day waiting period after a failed first attempt before retaking. The certificate, once granted, is valid for three years subject to CPD requirements and an annual maintenance fee.

How should I prepare for a closed-book PECB Foundation exam?

Because no materials are allowed, you must memorise the structure of ISO/IEC 27002:2022 (four themes, 93 controls), the purpose of key controls, and the fundamental concepts. Use timed practice questions to build recall speed — 40 questions in 60 minutes leaves about 90 seconds per question. Focus on distinguishing similar controls (for example 5.19 vs 5.20, or 8.15 vs 8.16) because the exam tests precise understanding.